Skip to content

Fix missing CVEs - #7

Merged
burisu merged 3 commits into
mainfrom
fix-missing-cves
Apr 20, 2026
Merged

burisu merged 3 commits into
mainfrom
fix-missing-cves

Conversation

@burisu

@burisu burisu commented Apr 20, 2026

Copy link
Copy Markdown
Contributor

No description provided.

@github-actions

Copy link
Copy Markdown

🏷️ [bumpr]
Next version:v0.2.3
Changes:v0.2.2...codeur:fix-missing-cves

@burisu
burisu marked this pull request as ready for review April 20, 2026 19:34
@burisu
burisu requested a review from Copilot April 20, 2026 19:34

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the RDJSON formatter and tests to handle yarn advisories that don’t include CVE identifiers by falling back to the advisory id and ensuring it’s emitted consistently.

Changes:

  • Coerce the advisory CVE/id value to a string before writing it to diagnostics[].code.value.
  • Add new test fixtures for an advisory with an empty cves array.
  • Improve the test script by normalizing JSON before diffing and adding a regression test for the “no CVE” case.

Reviewed changes

Copilot reviewed 4 out of 4 changed files in this pull request and generated 2 comments.

File Description
rdjson_formatter/rdjson_formatter.rb Ensures code.value is always string-typed when falling back to advisory id.
test/rdjson_formatter/test.sh Adds JSON-normalized comparison and a new test path for advisories without CVEs.
test/rdjson_formatter/testdata/advisory_without_cve.jsonl New JSONL input fixture representing an advisory without CVEs.
test/rdjson_formatter/testdata/advisory_without_cve.ok New expected RDJSON output snapshot for the “no CVE” scenario.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread test/rdjson_formatter/test.sh Outdated
Comment thread test/rdjson_formatter/test.sh Outdated
burisu and others added 2 commits April 20, 2026 21:38
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
@burisu
burisu merged commit 6519f8a into main Apr 20, 2026
6 checks passed
@burisu
burisu deleted the fix-missing-cves branch April 20, 2026 19:47
@github-actions

Copy link
Copy Markdown

🚀 [bumpr] Bumped!
New version:v0.2.3
Changes:v0.2.2...v0.2.3

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Development

Successfully merging this pull request may close these issues.

2 participants